6.5
CVE-2025-55225 - Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
7
CVE-2025-55223 - DirectX Graphics Kernel Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
7.5
CVE-2025-54919 - Windows Graphics Component Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
8.8
CVE-2025-54918 - Windows NTLM Elevation of Privilege Vulnerability
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
7.8
CVE-2025-54916 - Windows NTFS Remote Code Execution Vulnerability
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
7.8
CVE-2025-54913 - Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-54908 - Microsoft PowerPoint Remote Code Execution Vulnerability
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
7.8
CVE-2025-54907 - Microsoft Office Visio Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
7.8
CVE-2025-54906 - Microsoft Office Remote Code Execution Vulnerability
Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.
7.1
CVE-2025-54905 - Microsoft Word Information Disclosure Vulnerability
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.